CVE-2018-20932: Medium severity cpanel vulnerability
Published Aug 1, 2019
·Updated
cPanel before 70.0.23 exposes Apache HTTP Server logs after creation of certain domains (SEC-406).
Affected Software
3 affected components
Cpanel Cpanel>=61.9999.55<62.0.42
Cpanel Cpanel>=67.9999.64<68.0.33
Cpanel Cpanel>=69.9999.122<70.0.23
Event History
Aug 1, 2019
CVE Published
via MITRE·03:48 PM
Data Sourced
via MITRE·03:48 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20932?
CVE-2018-20932 has been categorized as a moderate severity vulnerability due to the exposure of sensitive Apache HTTP Server logs.
2
How do I fix CVE-2018-20932?
To remediate CVE-2018-20932, upgrade your cPanel installation to version 70.0.23 or later.
3
What impact does CVE-2018-20932 have on my system?
CVE-2018-20932 may lead to unauthorized access to sensitive information in Apache HTTP Server logs.
4
Which versions of cPanel are affected by CVE-2018-20932?
CVE-2018-20932 affects cPanel versions prior to 70.0.23, including specific versions within 61.x, 62.x, and 68.x.
5
Is there a workaround for CVE-2018-20932?
There is no documented workaround for CVE-2018-20932; updating to the latest version is the recommended solution.